Como configurar o syslog no F-Safer
Necessário abertura de ticket, a intervenção é feita em linha de código dentro da appliance.
/opt/fsafer/config/config.txt
Syslog Configuration
SYSLOG_ENABLE=true SYSLOG_ADDR=10.1.12.116:514 # Syslog server IP and port SYSLOG_FACILITY=local2 # Corresponds to the Syslog configuration file
Após alterar será necessário reiniciar os serviços do F-Safer
Analyzing Syslog Information
Event Type | Syslog Record Example |
---|---|
Login | Apr 19 15:25:11 10.1.14.125 fsafer: login_log - {"backend": "Password", "backend_display": "password", "city": "local", "datetime": "2023/04/19 15:18:36 +0800", "id": "cfc378e5-6337-4bf9-a8ac-15f33c2b0314", "ip": "10.1.10.35", "mfa": {"label": "disabled", "value": 0}, "reason": "", "reason_display": "", "status": {"label": "successful", "value": true}, "type": {"label": "Web", "value": "W"}, "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, Gecko) Chrome/112.0.0.0 Safari/537.36 Edg/112.0.1722.48", "username": "admin"} |
File Upload | Apr 19 15:27:26 10.1.14.125 fsafer: ftp_log - {"account": "root(root)", "asset": "10.1.12.182-root(10.1.12.182)", "date_start": "2023/04/19 15:20:51 +0800", "filename": "/tmp/vmware-root/file.pdf", "id": "6e7721c0-2091-49fb-8853-fc18e0a2e432", "is_success": true, "operate": {"label": "uploading", "value": "upload"}, "org_id": "00000000-0000-0000-0000-000000000002", "remote_addr": "10.1.10.35", "user": "Administrator(admin)"} |
File Download | Apr 19 15:28:08 10.1.14.125 fsafer: ftp_log - {"account": "root(root)", "asset": "10.1.12.182-root(10.1.12.182)", "date_start": "2023/04/19 15:21:33 +0800", "filename": "/tmp/vmware-root/file.pdf", "id": "113c0601-80c1-47d1-a053-5038fd89698c", "is_success": true, "operate": {"label": "downloading", "value": "download"}, "org_id": "00000000-0000-0000-0000-000000000002", "remote_addr": "10.1.10.35", "user": "Administrator(admin)"} |